Pandorex
Security

GitLab Fixes Two CVSS 9.9 Flaws in Regular-Expression Processing

Published Pandorex Redaktion·2 min read
—
Illustration: a crafted regex breaks through a CI/CD parser and routes a red attack path to a GitLab server.
Editorial illustration · Pandorex

In brief: GitLab has fixed two critical memory-safety flaws that let an authenticated user execute arbitrary server-side code through crafted regular expressions in a CI/CD configuration. CE/EE 19.2+ are affected; fixes are available in 19.2.7, 19.3.3 and 19.4.1. The update is urgent, although its database migrations can cause downtime on single-node installations.

Confirmed: RCE through regex processing

CVE-2026-89078 is a double free while parsing a specially crafted regular expression; CVE-2026-93577 is an integer overflow during compilation. GitLab rates both at CVSS 9.9. The vector is remotely reachable, requires low privileges and needs no interaction from another user. CVE-2026-93577 can fully affect confidentiality, integrity and availability according to its vector, while CVE-2026-89078 carries a lower availability impact.

All 19.2 releases before 19.2.7, 19.3 releases before 19.3.3 and 19.4 releases before 19.4.1 are vulnerable. GitLab.com is patched; Dedicated customers need no action. Self-managed operators should update immediately. On single-node systems, the included database migrations must finish before GitLab starts, causing an interruption. Multi-node deployments can use GitLab's zero-downtime procedure.

The release also fixes stored cross-site scripting in the merge-request diff viewer (CVE-2026-84739, CVSS 8.7) and several authorization defects. One GitLab EE issue could expose sensitive CI/CD variables from debug traces through the Duo AI troubleshooting feature.

Pandorex Analysis: authentication is not a strong barrier

The authentication requirement narrows the attack surface but does not make the flaws benign. The CVSS vector specifies only low privileges. On instances with open registration or compromised developer accounts, an ordinary account can therefore become a route to code execution on the GitLab server. Until patching is complete, operators should inspect new accounts, CI/CD configuration changes and unusual server processes rather than checking only the installed version.

GitLab's advisory does not report active exploitation or a public proof of concept. That is not an all-clear: GitLab plans to disclose the underlying issues only 90 days after the patch. Golem's core reporting on the causes, severity and fixed versions matches the primary source.

Sources and references

Sources used for the facts and context in this article.

  1. GitLab, 23.09.2026: Critical Patch Release 19.4.1, 19.3.3, 19.2.7docs.gitlab.com
  2. Golem.de, 25.09.2026: Angreifer können GitLab-Instanzen kaperngolem.de

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Storm-2570: One Ransomware Affiliate Changes Brands, Not Its Attack Pattern

Security